Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
A flaw was found in SSSD, where the sssctl command was vulnerable to shell command injection via the logs-fetch and cache-expire subcommands. This flaw allows an attacker to trick the root user into running a specially crafted sssctl command, such as via sudo, to gain root access. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
CVSS Information
N/A
Vulnerability Type
在命令中使用的特殊元素转义处理不恰当(命令注入)
Vulnerability Title
SSSD 操作系统命令注入漏洞
Vulnerability Description
SSSD是一款提供本地或远程身份和身份验证资源访问的守护程序。 SSSD 存在操作系统命令注入漏洞,该漏洞源于在SSSD中发现了一个缺陷,sssctl命令很容易通过log -fetch和cache-expire子命令注入shell命令。攻击者可利用该漏洞诱骗用户运行一个特别设计的sssctl命令,来威胁系统的机密性、完整性以及系统可用性。
CVSS Information
N/A
Vulnerability Type
N/A